Description
|
|
Multiple vulnerabilities have been identified in CA Total Defense, which could be exploited by remote attackers to gain knowledge of sensitive information, manipulate SQL queries, or compromise a vulnerable server.
The first issues are caused by input validation errors in the Unified Network Control (UNC) Server when processing user-supplied parameters, which could be exploited to conduct SQL injection attacks and execute arbitrary code with SYSTEM privileges.
The second vulnerability is caused due to insufficient validation of file upload parameters in the Management Server, which could allow remote unauthenticated to upload a malicious file and execute arbitrary code.
The third issue is caused by an error in the "management.asmx" module within the Unified Network Control (UNC) Server, which could allow remote unauthenticated attackers to obtain the server's database credentials and execute arbitrary code.
|